Swanbridge
Legal & Compliance

Privacy Policy

Last updated: August 28, 2026

At Swanbridge, we believe enterprise data synchronization must be transparent, secure, and privacy-preserving. This Privacy Policy outlines how we handle your credentials, metadata, and data streams when you use our platform.

1. Information We Collect

We collect information strictly necessary to operate our integration workflows: account details (email address and workspace identity), encrypted authorization tokens via OAuth, connection metadata (such as Notion database names, Google Sheet IDs, Jira project keys, and Airtable Base references), and execution telemetry (task run status, timestamps, row counts, and masked diagnostic error codes).

2. Zero Payload Retention (Ephemeral In-Memory Transit)

Swanbridge operates on a strict Zero Payload Retention model. We do not store, persist, or inspect the business records or data payloads synchronized between your connected systems. All data flows entirely in-memory through secure, ephemeral streaming channels directly from your authorized source to your designated destination.

3. Third-Party SaaS Integrations & Granular Scopes

When you authorize third-party platforms (such as Notion, Google Sheets, Jira, or Airtable), we request only the minimal permissions required to read selected datasets or write to designated target spreadsheets. You retain full control over your authorizations and can disconnect any provider at any time directly through the Swanbridge dashboard or within the third-party provider's account security settings.

4. Google API Services User Data Policy & Limited Use Disclosure

Swanbridge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (a) We only request access to Google Sheets and Google Drive metadata to perform user-configured data synchronization tasks; (b) We do not transfer or disclose Google user data to third parties, advertising platforms, or data brokers; (c) We do not use Google user data to train, retrain, or fine-tune general AI or machine learning models; (d) No human is permitted to read or inspect your Google user data unless you provide explicit consent for troubleshooting, or as required by applicable law.

5. Data Retention, Revocation & Deletion Policy

You have complete control over your data lifecycle. Because all synchronization is transit-only, no business records are retained after task completion. OAuth tokens and connection credentials stored in Supabase Vault are permanently destroyed immediately upon deleting a connection in your workspace or revoking permissions in your Google/Notion account settings. To request full deletion of your account, workspace metadata, or audit records, contact us at privacy@swanbridge.app.

6. Multi-Tenant Security & Credential Isolation

Security is built into every layer of Swanbridge. All OAuth tokens and secrets are encrypted at rest using envelope encryption in Supabase Vault. Every database table enforces PostgreSQL Row Level Security (RLS) to ensure absolute cryptographic tenant isolation. Diagnostic logs automatically mask and redact sensitive tokens, keys, and parameters before they are displayed or saved.

7. Contact & Compliance Inquiries

If you have any questions, compliance inquiries, or data deletion requests regarding this Privacy Policy or our third-party integrations, please contact our compliance team at privacy@swanbridge.app or support@swanbridge.app.